*** egonzalez has joined #openstack-kayobe | 07:16 | |
*** egonzalez has quit IRC | 08:41 | |
*** egonzalez has joined #openstack-kayobe | 08:46 | |
*** egonzalez has quit IRC | 08:58 | |
*** ktibi has joined #openstack-kayobe | 09:10 | |
*** mgoddard_ has joined #openstack-kayobe | 09:27 | |
ktibi | mgoddard, Hi mark, do you know if kolla or kayobe can config the iptables of host ? | 09:43 |
---|---|---|
ktibi | because for now, I have a lot of open ports on my ctrl or compute :/ | 09:44 |
mgoddard_ | ktibi: hi, neither kolla nor kayobe supports iptables currently | 09:45 |
ktibi | how do you fix your firewall ? | 09:46 |
mgoddard_ | manually currently | 09:46 |
ktibi | ok ^^ | 09:55 |
ktibi | maybe can add to kayobe the conf of firewall ? | 09:55 |
mgoddard_ | we've considered it | 10:01 |
mgoddard_ | the problem is that people use different tools to do firewall config, and they don't always work together | 10:02 |
mgoddard_ | plus it requires knowledge of services deployed by kolla, which really belongs in kolla-ansible | 10:02 |
*** egonzalez has joined #openstack-kayobe | 10:50 | |
*** ktibi_ has joined #openstack-kayobe | 11:11 | |
*** ktibi has quit IRC | 11:12 | |
*** ktibi_ is now known as ktibi | 13:13 | |
*** mgoddard has quit IRC | 15:00 | |
*** mgoddard has joined #openstack-kayobe | 15:02 | |
ktibi | mgoddard, do you have idea how can we add a custom CA in image during the build ? | 15:55 |
mgoddard_ | ktibi: custom image header/footers? | 15:55 |
ktibi | ^^ no docker image with kolla-build :p | 15:56 |
mgoddard_ | e.g. https://github.com/SKA-ScienceDataProcessor/alaska-kayobe-config/blob/alaska-prod/etc/kayobe/kolla.yml#L90 | 15:56 |
ktibi | ho yes :) | 15:56 |
mgoddard_ | no docker image? | 15:56 |
ktibi | I thought you were talking about image like jpg ^^ | 15:56 |
ktibi | ok great, can I use a generic block for add on all image ? | 15:57 |
mgoddard_ | base_footer? | 15:58 |
ktibi | works ? | 15:58 |
mgoddard_ | https://docs.openstack.org/kolla/latest/admin/image-building.html#dockerfile-customisation | 15:58 |
ktibi | ok, I added custom dockerfile for horizon (add designate dashboard), I did't see that :p | 15:59 |
mgoddard_ | most images have <image>_header and <image>_footer blocks that you can override, the kayobe config is just a bit of magic to define them in yaml | 15:59 |
mgoddard_ | yeah, it's fairly flexible | 16:00 |
ktibi | very good :) | 16:00 |
ktibi | I work on SSL on internal network | 16:00 |
mgoddard_ | you don't have a trusted CA? | 16:01 |
ktibi | add CA in image, change internal_protocol to https for API, config rabbitMQ for SSL and we good I think | 16:01 |
egonzalez | ktibi, copy the CA image will require the usage of a COPY in dockerfile, which will need the CA in the same folder as the dockerfile | 16:02 |
mgoddard_ | egonzalez: that's true | 16:02 |
egonzalez | ktibi, if possible use a curl or something to retrieve it from some other place | 16:03 |
egonzalez | will be easier to maintain | 16:03 |
ktibi | egonzalez, yep, thx for tips. | 16:04 |
mgoddard_ | ktibi: sorry... https://git.openstack.org/cgit/openstack/kayobe | 16:05 |
mgoddard_ | :) | 16:05 |
ktibi | egonzalez, mgoddard_ I think kolla doen't need a lot of modif for SSL on internal | 16:06 |
ktibi | goodbye github T_T | 16:06 |
mgoddard_ | ktibi: depends on the use case, there will probably be lots of corner cases that are hard to find | 16:07 |
mgoddard_ | I'm sure you could get it to work for a specific environment though | 16:07 |
ktibi | For me, API is easy, just rabbitmq more complex :/ | 16:08 |
*** egonzalez has quit IRC | 16:10 | |
ktibi | mgoddard_, did you go to PTG ? | 16:18 |
mgoddard_ | ktibi: yes I did. It was a good week | 16:19 |
ktibi | cold week? ;p | 16:19 |
mgoddard_ | Very cold | 16:19 |
mgoddard_ | Was stranded in dublin over the weekend! | 16:19 |
ktibi | yes same in france this week | 16:20 |
ktibi | at TV, they call that : moscou wave | 16:20 |
mgoddard_ | :) | 16:21 |
mgoddard_ | we called it 'the beast from the east' | 16:21 |
ktibi | but you re used to being cold in UK no ? | 16:24 |
mgoddard_ | not that cold... | 16:25 |
mgoddard_ | ktibi: if you're doing TLS, you may be interested in this: https://github.com/stackhpc/kayobe/pull/137 | 17:12 |
*** mgoddard_ has quit IRC | 17:45 | |
*** ktibi has quit IRC | 18:14 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!